<?xml version="1.0" encoding="UTF-8" standalone="no"?>
<?xml-stylesheet type="text/xsl" href="../part2stratml.xsl"?><PerformancePlanOrReport><Name>About The Open Web Application Security Project</Name><Description>The OWASP Foundation came online on December 1st, 2001 it was established as a not-for-profit charitable organization in the United States on April 21, 2004, to ensure the ongoing availability and support for our work at OWASP. OWASP is an international organization and the OWASP Foundation supports OWASP efforts around the world. OWASP is an open community dedicated to enabling organizations to conceive, develop, acquire, operate, and maintain applications that can be trusted. All of the OWASP tools, documents, forums, and chapters are free and open to anyone interested in improving application security. We advocate approaching application security as a people, process, and technology problem because the most effective approaches to application security include improvements in all of these areas. We can be found at www.owasp.org.</Description><OtherInformation>OWASP is a new kind of organization. Our freedom from commercial pressures allows us to provide unbiased, practical, cost-effective information about application security. OWASP is not affiliated with any technology company, although we support the informed use of commercial security technology. Similar to many open-source software projects, OWASP produces many types of materials in a collaborative and open way. The OWASP Foundation is a not-for-profit entity that ensures the project's long-term success.</OtherInformation><StrategicPlanCore><Organization><Name>Open Web Application Security Project</Name><Acronym>OWASP</Acronym><Identifier>_dfc8924a-1786-11ea-b175-0cbd2c83ea00</Identifier><Description/><Stakeholder StakeholderTypeType="Generic_Group"><Name>OWASP Global Board Members</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Person"><Name>Martin Knobloch</Name><Description>Chairman -- The Chairman of the Board shall serve as the principal executive officer of the Foundation.Fiduciary responsibilities: He/She shall, in general, supervise and control all of the business and affairs of the Foundation. He/She will monitor financial planning and financial reports He/She or he may sign, with the Secretary or any other proper officer of the Foundation thereunto authorized by the Board of Directors, any deeds, mortgages, bonds, contracts, or other instruments which the Board of Directors has authorized to be executed, except in cases where the signing and execution thereof shall be expressly delegated by the Board of Directors or by these Bylaws to some other officer or agent of the Foundation or shall be required by law to be otherwise signed or executed;Leadership and Direction: provides leadership to the Board of Directors with regards to policy setting and strategic planning. He/She helps guide and mediate board actions with respect to organizational priorities and governance concerns, and in general, shall perform all duties incident to the office of Chairman of the Board subject to the control of the Board of Directors.Organizational Responsibilities: He/She plays a leading role in fundraising activities, formally evaluate the performance of the Foundation Director and informally evaluate the effectiveness of the board members. An annual, overall evaluation of the performance of the organization in achieving its mission will be accomplished. He or she shall, when present, preside at all meetings of the Board of Directors unless otherwise delegated, and such other duties as may be prescribed by the Board of Directors from time to time.</Description></Stakeholder><Stakeholder StakeholderTypeType="Person"><Name>Owen Pendlebury</Name><Description>Vice Chairman -- Performs Chair responsibilities when the Chair cannot be available, works closely with Chair and other Board Members, participates closely with Chair to develop and implement officer transition plans, performs other responsibilities as assigned by the Board. </Description></Stakeholder><Stakeholder StakeholderTypeType="Person"><Name>Sherif Mansour</Name><Description>Treasurer -- Treasurer ­manages finances of the organization, administers fiscal matters of the organization, provides annual budget to the board for member’s approval, ensures development and board review of financial policies and procedures.</Description></Stakeholder><Stakeholder StakeholderTypeType="Person"><Name>Ofer Maor</Name><Description>Secretary -- Maintains records of the board and ensures effective management of organization’s records, manages minutes of board meetings, ensures minutes are distributed shortly after each meeting, is sufficiently familiar with legal documents (articles, by­laws, IRS letters, etc.) to note applicability during meetings; is the custodian of the corporate records and of the seal of the Foundation and see that the seal of the Foundation is affixed to all documents, the execution of which on behalf of the Foundation under its seal is duly authorized; keeps a register of the post office address of each Director which shall be furnished to the Secretary by such Director; and, in general perform all duties incident to the office of the Secretary and such other duties as from time to time may be assigned to him by the Chairman of the Board or by the Board.</Description></Stakeholder><Stakeholder StakeholderTypeType="Person"><Name>Richard Greenberg</Name><Description>Member at Large</Description></Stakeholder><Stakeholder StakeholderTypeType="Person"><Name>Gary Robinson</Name><Description>Member at Large</Description></Stakeholder><Stakeholder StakeholderTypeType="Person"><Name>Chenxi Wang</Name><Description>Member at Large</Description></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name>OWASP Foundation Staff</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Person"><Name>Mike McCamon</Name><Description>Executive Director,Kansas -- The Executive Director is ultimately responsible for overseeing the administration, programs and strategic plan of the organization.</Description></Stakeholder><Stakeholder StakeholderTypeType="Person"><Name>Emily Berman</Name><Description>Director of Events, Colorado -- The Director of Events is responsible for the success of the Company’s event programming including global events and other initiatives. Additionally the Events Director will collaborate with leaders, members, and partners to grow and evolve our regional and local events.</Description></Stakeholder><Stakeholder StakeholderTypeType="Person"><Name>Harold Blankenship</Name><Description>Director of Technology &amp; Projects,Texas -- The Director of Technology &amp; Projects nurtures, manages, facilitates, and supports the volunteer open source programs of the Foundation. Additionally the Director of Technology &amp; Projects will, with the support of staff and partners, champion, manage, and execute the technology roadmap of the Foundation.</Description></Stakeholder><Stakeholder StakeholderTypeType="Person"><Name>Kelly Santalucia</Name><Description>Director of Corporate Support, New Jersey -- The Director of Corporate Support identifies, nurtures, develops, documents, solicits, and closes sponsorships and grants for the Foundation and its mission. Also the Director of Corporate Support will collaborate with staff, leaders, and members to improve our membership and events offerings for partners.</Description></Stakeholder><Stakeholder StakeholderTypeType="Person"><Name>Dawn Aitken</Name><Description>Community &amp; Operations Manager, Florida -- The Community &amp; Operations Manager proactively runs the Foundation’s core business and chapter functions in a professional, consistent, efficient, and cost-effective manner. Generally these functions include opening and closing local chapters; proactively supporting chapter leaders; regularly ensuring the accuracy and integrity of chapter, member and other data; leadership and primary liaison for accounts payable; and semi-annually audit processes and signatory authorities ensuring issues are resolved. Additionally the Community &amp; Operations Manager along with support from staff and partners will accurately document and implement the policies of the Foundation.</Description></Stakeholder><Stakeholder StakeholderTypeType="Person"><Name>Lisa Jones</Name><Description>Sales &amp; Marketing Operations Manager, North Carolina -- The Sales &amp; Marketing Operations Manager supports and coordinates core communication, promotional, member, and sales functions of the Foundation. Generally these functions include the development and execution of professional, regular, and impactful communications in both long and short form through email marketing and social media; proactively leading, managing, and facilitating co-marketing programs; regularly ensuring the accuracy and integrity of member data; supporting and assisting potential individual members; execution of and primary liaison for invoicing and accounts receivable; and ensure corporate member and sponsor benefits are delivered accurately and on schedule.</Description></Stakeholder><Stakeholder StakeholderTypeType="Person"><Name>Sibah Poede</Name><Description>Events Coordinator,U.K. -- Organize logistical and administrative support for while coordinating with sales team to develop the strategy and direction of events. Collaborate with the marketing and design teams to facilitate event promotion. Support staff in managing budgets, calendars, and partnerships for event efforts. Collaborate with leaders, members, and partners to grow and evolve regional events.</Description></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name>OWASP Members &amp; Participants</Name><Description>Participation and Membership -- Everyone is welcome to participate in our forums, projects, chapters, and conferences. OWASP is a fantastic place to learn about application security, to network, and even to build your reputation as an expert. https://www.owasp.org/index.php/MembershipIf you find the OWASP materials valuable, please consider supporting our cause by becoming an OWASP member. All monies received by the OWASP Foundation go directly into supporting OWASP projects.For more information, please see the Membership page.</Description></Stakeholder></Organization><Vision><Description>Be the thriving global community that drives visibility and evolution in the safety and security of the world’s software.</Description><Identifier>_dfc89330-1786-11ea-b175-0cbd2c83ea00</Identifier></Vision><Mission><Description>To enable organizations to conceive, develop, acquire, operate, and maintain applications that can be trusted.</Description><Identifier>_dfc893f8-1786-11ea-b175-0cbd2c83ea00</Identifier></Mission><Value><Name>Openness</Name><Description>Everything at OWASP is radically transparent from our finances to our code.</Description></Value><Value><Name>Innovation</Name><Description>OWASP encourages and supports innovation and experiments for solutions to software security challenges.</Description></Value><Value><Name>Participation</Name><Description>GLOBAL --- Anyone around the world is encouraged to participate in the OWASP community.</Description></Value><Value><Name>Integrity</Name><Description>OWASP is an honest and truthful, vendor neutral, global community.</Description></Value><Value><Name>Ethics</Name><Description>Code of Ethics -- Each of us is expected to behave according to the principles contained in the following Code of Ethics. Breaches of the Code of Ethics may result in the foundation taking disciplinary action. Membership Revocation: https://www.owasp.org/index.php/Membership_Revocation* Perform all professional activities and duties in accordance with all applicable laws and the highest ethical principles;* Promote the implementation of and promote compliance with standards, procedures, controls for application security;* Maintain appropriate confidentiality of proprietary or otherwise sensitive information encountered in the course of professional activities;* Discharge professional responsibilities with diligence and honesty;* To communicate openly and honestly;* Refrain from any activities which might constitute a conflict of interest or otherwise damage the reputation of employers, the information security profession, or the Association;* To maintain and affirm our objectivity and independence;* To reject inappropriate pressure from industry or others;* Not intentionally injure or impugn the professional reputation of practice of colleagues, clients, or employers;* Treat everyone with respect and dignity; and* To avoid relationships that impair — or may appear to impair — OWASP's objectivity and independence.</Description></Value><Value><Name>Principles</Name><Description>* Free &amp; Open* Governed by rough consensus &amp; running code* Abide by a code of ethics (see ethics)* Not-for-profit* Not driven by commercial interests* Risk-based approach</Description></Value><Goal><Name>Code Security</Name><Description>Help organizations produce secure code</Description><Identifier>_dfc894f2-1786-11ea-b175-0cbd2c83ea00</Identifier><SequenceIndicator/><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>ProjectsOWASP's projects cover many aspects of application security. We build documents, tools, teaching environments, guidelines, checklists, and other materials to help organizations improve their capability to produce secure code.For details on all the OWASP projects, please see the OWASP Project page: https://www.owasp.org/index.php/Category:OWASP_Project</OtherInformation><Objective><Name>Documents</Name><Description>Build documents</Description><Identifier>_dfc895b0-1786-11ea-b175-0cbd2c83ea00</Identifier><SequenceIndicator>1</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Tools</Name><Description>Build tools</Description><Identifier>_dfc8966e-1786-11ea-b175-0cbd2c83ea00</Identifier><SequenceIndicator>2</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Teaching</Name><Description>Build teaching environments</Description><Identifier>_dfc8972c-1786-11ea-b175-0cbd2c83ea00</Identifier><SequenceIndicator>3</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Guidelines</Name><Description>Build guidelines</Description><Identifier>_dfc897ea-1786-11ea-b175-0cbd2c83ea00</Identifier><SequenceIndicator>4</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Checklists</Name><Description>Build checklists</Description><Identifier>_dfc898a8-1786-11ea-b175-0cbd2c83ea00</Identifier><SequenceIndicator>5</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Other Materials</Name><Description>Build other materials</Description><Identifier>_dfc89966-1786-11ea-b175-0cbd2c83ea00</Identifier><SequenceIndicator>6</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective></Goal></StrategicPlanCore><AdministrativeInformation><StartDate>2001-12-01</StartDate><EndDate/><PublicationDate>2019-12-05</PublicationDate><Source>https://www.owasp.org/index.php/About_The_Open_Web_Application_Security_Project</Source><Submitter><GivenName>Owen</GivenName><Surname>Ambur</Surname><PhoneNumber/><EmailAddress>Owen.Ambur@verizon.net</EmailAddress></Submitter></AdministrativeInformation></PerformancePlanOrReport>
